Privacy
notice
Pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).
1. Data controller
LVE S.r.l. — Via Niccolò Tommaseo 78/C, 35131 Padua (PD), Italy
VAT & Tax code 05774170285 — Padua Companies Register 34820/2026 — REA PD 491526
Share capital €50,000 fully paid up — Sole-shareholder company
Email: info@lve.live — Certified mail:lvesrl@legalmail.it
No Data Protection Officer has been appointed, as the conditions set out in Article 37 GDPR do not apply. For any matter concerning personal data, please write to the addresses above.
2. Who this notice is for
The data we process depends on how you come into contact with us. This notice distinguishes two situations, because the data, the purposes and the retention periods differ:
- A — Site visitors: anyone browsing lve.live who sends the contact form or a quotation request.
- B — Rental customers: anyone entering into a rental agreement (LVE Rent), signing it online and taking delivery of an asset.
3. Data we process
A — Site visitors.
From the contact form: name, email address,company (optional) and the message. From an LVE Rent quotation request: first and last name, email, phone, requested asset, dates, delivery location and any notes.
B — Rental customers. In addition to identity and contact details:
- tax code, place and date of birth, residence, needed to identify the contracting party;
- driving licence — number, issuing authority and date, and aphotograph of the document, front and back;
- identity document — photograph of the front and, where applicable, the back;
- additional drivers' details, where named;
- electronic signature records: the email address the one-time code was sent to, the date and time of signing, and the IP address it was signed from;
- handover and return records: odometer reading, fuel level, condition of the asset and photographs of the vehicle, the odometer and any damage;
- payment data: amount, reference, chosen method, transaction identifier.Card details never pass through our systems and are not stored by us: they are collected directly by the payment provider (see section 7). For bank transfers we process the details shown on the credit advice.
We do not process special categories of data (Article 9 GDPR). If irrelevant information appears in a photograph or a note, please tell us and we will remove it.
4. Purposes and legal bases
- Answering enquiries received through the site and preparing quotations — pre-contractual measures taken at the data subject's request (Article 6(1)(b) GDPR).
- Entering into and performing the rental agreement: identifying the party and the driver, verifying entitlement to drive, handing over and taking back the asset, handling payments and the security deposit (Article 6(1)(b) GDPR).
- Complying with legal obligations: tax and accounting record-keeping, insurance obligations, and the duty to disclose the driver's details to the authorities in the event of road traffic offences (Article 126-bis of the Italian Highway Code) — Article 6(1)(c) GDPR.
- Protecting our rights: documenting the condition of the asset at handover and return, establishing damage or excess mileage, defending ourselves in the event of a payment dispute or litigation, preventing fraud and misuse of the asset — legitimate interest of the controller (Article 6(1)(f) GDPR).
- Sending marketing communications about similar services, only where you have given consent, which you may withdraw at any time (Article 6(1)(a) GDPR).
5. Whether providing data is required
For the contact form, your name, email and message are needed so that we can reply; the company field is optional.
For a rental, providing identity details, the driving licence and the identity document isrequired: without them we cannot enter into the agreement or hand over the asset, since we are obliged to verify the driver's identity and entitlement to drive. Consent to marketing communications is free and optional: refusing it has no effect on the rental.
6. Retention periods
- Site enquiries and quotations that did not proceed: 24 months.
- Agreement, tax and accounting records: 10 years from the end of the relationship, as required by Article 2220 of the Italian Civil Code and by tax law.
- Copies of the driving licence and identity document: up to 12 months after the asset is returned, being the period within which administrative penalties relating to the rental may arrive; after that the copies are deleted, unless they are needed for ongoing proceedings.
- Handover and return reports and photographs: they are annexes to the agreement and follow its retention period.
- Electronic signature records (email, date, time, IP address): 10 years together with the agreement, as evidence that it was signed.
- Marketing consent: until withdrawn, and in any case no longer than 24 months from the last contact.
7. Recipients and processors
Data may be processed by suppliers acting as processors, appointed under Article 28 GDPR:
- Supabase — database and storage for uploaded documents (servers in the European Union, Frankfurt);
- Cloudflare — hosting and content delivery;
- Resend — sending service emails, agreements and reports (servers in the European Union, Ireland);
- Stripe Payments Europe Ltd. — card payments, security deposit holds and fraud checks. Stripe acts as an independent controller for the anti-money-laundering and fraud-prevention duties imposed on it by law.
- Google Workspace — company email.
Data may also be disclosed to:
- insurers and loss adjusters, in the event of an accident or damage;
- competent authorities, where the law requires it, in particular to identify the driver in the event of road traffic offences;
- professional advisers (accountants, lawyers) for obligations connected with the relationship;
- banks, to execute payments.
Data is never disseminated or sold to third parties for commercial purposes.
8. Transfers outside the European Economic Area
Some suppliers belong to groups with companies in the United States and may process data outside the European Economic Area. Where that happens, the transfer takes place on the basis of appropriate safeguards: Standard Contractual Clauses approved by the European Commission, adequacy decisions, or both. You may ask us for a copy of the safeguards in place by writing to the addresses in section 1.
9. Automated checks on payments
Card payments are subject to automated fraud checks carried out by the payment provider, which may result in a transaction being declined. This is a measure necessary to prevent fraud, and is also required by payment services legislation.
A declined payment does not in itself produce further legal effects concerning you, and does not prevent the rental from being completed by another method. In any event you have the right to obtain human intervention, to express your point of view and to contest the decision, by writing to the addresses in section 1.
Beyond this, we carry out no solely automated decision-making and no profiling within the meaning of Article 22 GDPR.
10. Your rights
You may at any time exercise the rights under Articles 15-22 GDPR: access, rectification, erasure, restriction, objection and data portability, as well as withdrawal of consent (which does not affect the lawfulness of processing already carried out). To exercise them, write to info@lve.live.
We will reply within one month. Some data cannot be erased before the period stated in section 6, where retention is required by law or necessary to defend a legal claim: in those cases we will tell you so and explain why.
You also have the right to lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it).
11. Cookies and similar technologies
This site uses no profiling, analytics or advertising cookies and therefore requires no consent banner. Typefaces are hosted on our own domain: displaying them involves no connection to third-party servers.
Only technical cookies necessary for the operation and security of the site may be present, set by the hosting provider (Cloudflare) to protect against automated traffic. In the reserved area and on the signing page, access uses browser local storage needed to keep the session.
On the contract signing page only, when you choose to pay by card, theStripe payment form is loaded from js.stripe.com. Stripe sets its own technical cookies, indispensable for fraud prevention and transaction security. These are not advertising or profiling tools, and they are not loaded on any other page of the site.
12. Security
We apply appropriate technical and organisational measures to protect data. Enquiries and agreements are stored in a database with restricted access, not publicly readable. Copies of licences and identity documents are held in private storage, accessible only to authorised staff and never reachable from a public address. The connection to the site is always encrypted. Access to the reserved area is named and logged.
13. Changes to this notice
The controller may update this notice to reflect changes in law or in its organisation. The version in force is always published on this page, with the date it was last updated.
Last updated: 23 August 2026.